spf-discuss
[Top] [All Lists]

Re: making the policy decision: leveraging HTTPS

2004-06-20 20:46:52
On Sun, 20 Jun 2004 12:26:20 -0400 (EDT), Meng Weng Wong wrote
Here's one more:

 given DOMAIN, attempt to connect to https://www.DOMAIN/.

 If an HTTPS connection succeeds, and the certificate for
 DOMAIN is valid, that makes it somewhat more likely that
 the sender is a good guy.

 And if the sender turns out to be a bad guy, the information
 in the SSL certificate will help the feds track them down.

This leverages the existing multimillion dollar
infrastructure already in place for HTTPS, and makes it
useful in the war against spam.

I don't like this one bit.  It suggests that someday I might have to pay 
hundreds of dollars to Verizon for an SSL cert just so I can send email.  
Unacceptable.